Fraudulent apps are designed to download malware to your device
If you look for applications for your Windows 11 laptop or desktop PC with Google, you should be on high alert.
Researchers have unearthed a network of more than 70 fake websites posing as well-known Windows tools, including Microsoft PowerToys, CrystalDiskMark, Wintoys, Lively Wallpaper, and SignalRGB. Even if you've never heard of them, these apps are highly rated and have thousands of downloads from the Microsoft Store.
If you've clicked on any of these apps from Google before, you should double-check your device.
That's because these copycat sites are designed to look like the real thing, but offer downloads for malware instead of the legitimate Windows 11 app. If you've downloaded what you thought was a trusted utility from one of these sites, your PC could actually be compromised with info-stealing software or even a remote-access Trojan — essentially giving attackers a backdoor into your machine.
And the really worrying part is that many of these apps appear higher in Google search results than the genuine article, so it's very easy to mistake the real apps.
The scam came to light thanks to the developer behind Wintoys, a handy Windows optimisation tool caught up in the scam. Going by the username Bogdan_X, they regularly search for their app's name on Google to keep tabs on new reviews and user feedback.
During one of those routine checks, a domain called wintoys.app popped up — an online site that had no affiliation with the legitimate app. It turned out to be a WordPress page filled with vague, Artificial Intelligence (AI)- generated text and an outdated version of the app's logo.
What makes this particularly sneaky is its download button actually pointed to the legitimate Microsoft Store listing, which is likely why nobody had flagged it sooner.
When Bogdan_X tried to find out who owned the domain, they hit a wall — it had been registered to hide buyer details by default. But digging further revealed a staggering 72 similar lookalike domains all tied to the same registration.
According to Check Point Research, these fake sites follow a three-step guide to help fool you.
First, they climb the search rankings by targeting popular app names. Then they play it safe for a while, actually linking to genuine download sources so visitors trust them and keep coming back.
Once they've built up enough traffic and credibility, the trap springs. A hidden script intercepts your click on the download button and routes you through what's called a Traffic Distribution System — a filter that decides what to serve you based on your location, browser, whether you're using one of the best VPNs, and whether you look like a security researcher.
Some unlucky visitors end up with malware like RemusStealer, which goes after browser data, passwords, and crypto wallets. Another one called AnimateClipper silently swaps cryptocurrency wallet addresses you've copied with the attacker's own.
Developers behind at least two of the impersonated apps have also confirmed that their fake sites are dishing out real malware. For instance, the creator of Lively Wallpaper — a popular app that lets you set animated wallpapers to your desktop — has said the copycat domain has zero connection to their project and pointed users towards the official Microsoft Store listing instead.
To protect your personal information and device, it's best to follow these three steps:
You can check and see if PUA is in use in your settings by doing the following:






